The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.
Volume of CVEs assigned to CWE-691 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
32 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-20559HIGH
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
| Apr 2, 2023 | 8.8 | 26 | NO | NO |
CVE-2025-25273HIGH Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enab | Aug 12, 2025 | 7.8 | 25 | NO | NO |
CVE-2025-22893HIGH Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enab | Aug 12, 2025 | 7.8 | 25 | NO | NO |
CVE-2021-4106HIGH A vulnerability in Snow Inventory Java Scanner allows an attacker to run malicious code at a higher level of privileges. This issue affects: SNOW Snow Inventory Java Scanner 1.0 | Feb 16, 2022 | 7.8 | 25 | NO | NO |
CVE-2026-5938MEDIUM Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service. | Apr 27, 2026 | 5.5 | 24 | NO | NO |
CVE-2025-24305HIGH Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a privileged user to potentially enable esc | Aug 12, 2025 | 7.2 | 24 | NO | NO |
CVE-2022-48481HIGH In JetBrains Toolbox App before 1.28 a DYLIB injection on macOS was possible | Apr 28, 2023 | 7.8 | 24 | NO | NO |
CVE-2025-35963HIGH Insufficient control flow management for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.160 within Ring 2: Device Drivers may allow a denial of service. | Nov 11, 2025 | 7.4 | 23 | NO | NO |
CVE-2024-29079HIGH Insufficient control flow management in some Intel(R) VROC software before version 8.6.0.3001 may allow an authenticated user to potentially enable escalation of privilege via loca | Nov 13, 2024 | 7.8 | 21 | NO | NO |
CVE-2024-37158HIGH Evmos is the Ethereum Virtual Machine (EVM) Hub on the Cosmos Network. Preliminary checks on actions computed by the clawback vesting accounts are performed in the ante handler. Ev | Jun 17, 2024 | 8.1 | 21 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.